This notice explains how Synci handles your personal data when you connect a financial account through the Synci portal. You have been sent here by an app you use (the "App").
Who is responsible for your data
The App is the data controller for your financial data. It decides why the data is collected and how it is used. Its privacy notice explains that. If you cannot find it, ask the App.
Synci (Tonning, doing business as Synci, org. no. 930076066, Nordbø 15, 5009 Bergen, Norway) is the App's data processor. We collect, store, and deliver your financial data to the App on the App's instructions. We do not use your financial data for our own purposes, do not sell it, and do not use it for marketing.
Synci is a data controller in its own right only for a narrow set of activities needed to run and protect the platform: keeping the service secure, preventing fraud and abuse, keeping business and billing records with the App, and producing anonymised statistics that cannot identify you.
The connectivity provider you connect through (the company that connects to your bank), for example GoCardless, is a separate data controller. It obtains your data from your bank under its own licence and its own privacy notice, which you see when you connect.
What data we process
- Your email address, a name, and, if the App chooses, the App's own reference for you. The App provides these when it registers you. We use your email address to sign you in to the portal (a one-time code if your link has expired) and, where the App has enabled it, to tell you about expiring, failing, or disabled connections. We also email you once if the App loses access to Synci, so you know your connections are no longer being read.
- Account details, balances, transactions, holdings, and connection status obtained from your financial institution through the connectivity provider.
- Where the App has enabled it, enrichment of transactions (for example merchant name and category).
- Technical data from your use of the portal: IP address, browser type, and the time and version of your acceptance of the portal terms.
Why and on what basis
We process your financial data because the App has instructed us to, under a data processing agreement with the App. The lawful basis for that processing is the App's to establish and explain to you.
For our own limited controller activities in section 1, our basis is legitimate interest (GDPR Art. 6(1)(f)) in operating a secure and lawful service, and legal obligation (Art. 6(1)(c)) where bookkeeping or other laws require it.
Who receives your data
- The App, which receives the financial data it has requested.
- The connectivity provider you connect through, which receives the details needed to establish and maintain the connection.
- Our sub-processors, which host and support our platform. The current list is below and is updated when it changes.
| Sub-processor | Purpose | Location |
|---|---|---|
| DigitalOcean | The Synci backend, database and backups, where your data is actually stored | EU |
| Vercel | Hosting and delivery of the portal, including the server-side layer through which API responses pass | US, under the safeguards in section 5 |
| Cloudflare | Network protection and security | US, under the safeguards in section 5 |
| Resend, with Mailgun as backup | Portal sign-in codes, and connection status emails where the App has enabled them | US, under the safeguards in section 5 |
| Google Workspace | Our support mailbox, if you email us | US, under the safeguards in section 5 |
| Featurebase | Our support helpdesk, if you email us | EU |
| Ntropy | Transaction enrichment, only where the App has enabled it | US entity, EU processing endpoint, under the safeguards in section 5 |
| Microsoft Azure AI Foundry | Transaction enrichment, only where the App has enabled it, deployed in Sweden | EU |
| Laravel Nightwatch | Error and performance monitoring | US, under the safeguards in section 5 |
The connectivity provider is not a sub-processor. It acts as an independent controller.
We disclose data to public authorities only where required by law.
International transfers
Your financial data is stored in the EU. Where a sub-processor processes data outside the EEA, the transfer is covered by the European Commission's Standard Contractual Clauses or an adequacy decision, with any EU-US Data Privacy Framework certification treated as supplementary. Connectivity providers outside the EEA, Akahu in New Zealand and SnapTrade in Canada, act as independent controllers in countries covered by EU adequacy decisions. Copies of the relevant safeguards are available on request.
How long we keep your data
The App sets the retention period for your financial data. Unless the App has configured otherwise, the period is 60 days or 730 days of transaction history depending on the App's plan. Data older than the configured period is deleted on a rolling basis. The shortest window the App can set is 7 days, which is needed to prevent sync errors and duplicates.
When you disconnect an account, no new data is collected from it. When the App deletes you or one of your connections, the stored financial data is deleted immediately and removed from backups within 30 days. If the App's relationship with Synci ends, your data is deleted or returned to the App on its instruction and in any event within 30 days, unless a law requires us to keep specific records longer.
Security and access logs are kept for up to 12 months, so we can investigate incidents. Records of your acceptance of the portal terms are kept for as long as your connection exists and for 3 years afterwards.
Your rights
You have the right to access, correct, delete, and receive a copy of your personal data, to object to or restrict processing, and to withdraw consent given to a connectivity provider.
Because the App is the controller of your financial data, send requests to the App first. We assist the App in responding and act on its instructions. If you contact us directly at support@synci.io, we will tell the App and help it respond, or respond ourselves where the request concerns our own controller activities.
You can disconnect an account at any time in the portal or in the App, and you can revoke the connectivity provider's access directly with your bank or the provider.
Complaints
You can complain to the Norwegian Data Protection Authority (Datatilsynet, datatilsynet.no) or to the supervisory authority in the country where you live. Complaints about the App's use of your data should be directed to the App or to its supervisory authority.
Changes
We update this notice when our processing changes. The version in force is shown at the top of this page.
Contact
Tonning, doing business as Synci
org. no. 930076066
Nordbø 15
5009 Bergen, Norway
support@synci.io